CVE-2023-46243
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Nov 7, 2023
Updated: Nov 15, 2023
CWE ID 94
Summary
CVE-2023-46243 is a vulnerability affecting the XWiki Platform, a wiki solution that offers runtime services for applications. In vulnerable versions, users with edit rights on a document can execute arbitrary Groovy code by crafting a malicious URL. The code execution occurs when the user edits the document and saves the new content. This vulnerability can lead to server compromise, making it essential for users to update to XWiki versions 14.10.6 or 15.2RC1 as soon as possible. No workarounds are currently available for this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Xwiki
Affected Vendors
- xwiki